| ATLAS | AML.T0000 | Search Open Technical Databases |
| ATLAS | AML.T0000.000 | Journals and Conference Proceedings |
| ATLAS | AML.T0000.001 | Pre-Print Repositories |
| ATLAS | AML.T0000.002 | Technical Blogs |
| ATLAS | AML.T0001 | Search Open AI Vulnerability Analysis |
| ATLAS | AML.T0002 | Acquire Public AI Artifacts |
| ATLAS | AML.T0002.000 | Datasets |
| ATLAS | AML.T0002.001 | Models |
| ATLAS | AML.T0002.002 | AI Agent Configuration |
| ATLAS | AML.T0003 | Search Victim-Owned Websites |
| ATLAS | AML.T0004 | Search Application Repositories |
| ATLAS | AML.T0005 | Create Proxy AI Model |
| ATLAS | AML.T0005.000 | Train Proxy via Gathered AI Artifacts |
| ATLAS | AML.T0005.001 | Train Proxy via Replication |
| ATLAS | AML.T0005.002 | Use Pre-Trained Model |
| ATLAS | AML.T0006 | Active Scanning |
| ATLAS | AML.T0007 | Discover AI Artifacts |
| ATLAS | AML.T0008 | Acquire Infrastructure |
| ATLAS | AML.T0008.000 | AI Development Workspaces |
| ATLAS | AML.T0008.001 | Consumer Hardware |
| ATLAS | AML.T0008.002 | Domains |
| ATLAS | AML.T0008.003 | Physical Countermeasures |
| ATLAS | AML.T0008.004 | Serverless |
| ATLAS | AML.T0008.005 | AI Service Proxies |
| ATLAS | AML.T0010 | AI Supply Chain Compromise |
| ATLAS | AML.T0010.000 | Hardware |
| ATLAS | AML.T0010.001 | AI Software |
| ATLAS | AML.T0010.002 | Data |
| ATLAS | AML.T0010.003 | Model |
| ATLAS | AML.T0010.004 | Container Registry |
| ATLAS | AML.T0010.005 | AI Agent Tool |
| ATLAS | AML.T0011 | User Execution |
| ATLAS | AML.T0011.000 | Unsafe AI Artifacts |
| ATLAS | AML.T0011.001 | Malicious Package |
| ATLAS | AML.T0011.002 | Poisoned AI Agent Tool |
| ATLAS | AML.T0011.003 | Malicious Link |
| ATLAS | AML.T0012 | Valid Accounts |
| ATLAS | AML.T0013 | Discover AI Model Ontology |
| ATLAS | AML.T0014 | Discover AI Model Family |
| ATLAS | AML.T0015 | Evade AI Model |
| ATLAS | AML.T0016 | Obtain Capabilities |
| ATLAS | AML.T0016.000 | Adversarial AI Attack Implementations |
| ATLAS | AML.T0016.001 | Software Tools |
| ATLAS | AML.T0016.002 | Generative AI |
| ATLAS | AML.T0017 | Develop Capabilities |
| ATLAS | AML.T0017.000 | Adversarial AI Attacks |
| ATLAS | AML.T0018 | Manipulate AI Model |
| ATLAS | AML.T0018.000 | Poison AI Model |
| ATLAS | AML.T0018.001 | Modify AI Model Architecture |
| ATLAS | AML.T0018.002 | Embed Malware |
| ATLAS | AML.T0019 | Publish Poisoned Datasets |
| ATLAS | AML.T0020 | Poison Training Data |
| ATLAS | AML.T0021 | Establish Accounts |
| ATLAS | AML.T0024 | Exfiltration via AI Inference API |
| ATLAS | AML.T0024.000 | Infer Training Data Membership |
| ATLAS | AML.T0024.001 | Invert AI Model |
| ATLAS | AML.T0024.002 | Extract AI Model |
| ATLAS | AML.T0025 | Exfiltration via Cyber Means |
| ATLAS | AML.T0029 | Denial of AI Service |
| ATLAS | AML.T0031 | Erode AI Model Integrity |
| ATLAS | AML.T0034 | Cost Harvesting |
| ATLAS | AML.T0034.000 | Excessive Queries |
| ATLAS | AML.T0034.001 | Resource-Intensive Queries |
| ATLAS | AML.T0034.002 | Agentic Resource Consumption |
| ATLAS | AML.T0035 | AI Artifact Collection |
| ATLAS | AML.T0036 | Data from Information Repositories |
| ATLAS | AML.T0037 | Data from Local System |
| ATLAS | AML.T0040 | AI Model Inference API Access |
| ATLAS | AML.T0041 | Physical Environment Access |
| ATLAS | AML.T0042 | Verify Attack |
| ATLAS | AML.T0043 | Craft Adversarial Data |
| ATLAS | AML.T0043.000 | White-Box Optimization |
| ATLAS | AML.T0043.001 | Black-Box Optimization |
| ATLAS | AML.T0043.002 | Black-Box Transfer |
| ATLAS | AML.T0043.003 | Manual Modification |
| ATLAS | AML.T0043.004 | Insert Backdoor Trigger |
| ATLAS | AML.T0044 | Full AI Model Access |
| ATLAS | AML.T0046 | Spamming AI System with Chaff Data |
| ATLAS | AML.T0047 | AI-Enabled Product or Service |
| ATLAS | AML.T0048 | External Harms |
| ATLAS | AML.T0048.000 | Financial Harm |
| ATLAS | AML.T0048.001 | Reputational Harm |
| ATLAS | AML.T0048.002 | Societal Harm |
| ATLAS | AML.T0048.003 | User Harm |
| ATLAS | AML.T0048.004 | AI Intellectual Property Theft |
| ATLAS | AML.T0049 | Exploit Public-Facing Application |
| ATLAS | AML.T0050 | Command and Scripting Interpreter |
| ATLAS | AML.T0051 | LLM Prompt Injection |
| ATLAS | AML.T0051.000 | Direct |
| ATLAS | AML.T0051.001 | Indirect |
| ATLAS | AML.T0051.002 | Triggered |
| ATLAS | AML.T0052 | Phishing |
| ATLAS | AML.T0052.000 | Spearphishing via Social Engineering LLM |
| ATLAS | AML.T0052.001 | Deepfake-Assisted Phishing |
| ATLAS | AML.T0053 | AI Agent Tool Invocation |
| ATLAS | AML.T0054 | LLM Jailbreak |
| ATLAS | AML.T0055 | Unsecured Credentials |
| ATLAS | AML.T0056 | Extract LLM System Prompt |
| ATLAS | AML.T0057 | LLM Data Leakage |
| ATLAS | AML.T0058 | Publish Poisoned Models |
| ATLAS | AML.T0059 | Erode Dataset Integrity |
| ATLAS | AML.T0060 | Publish Hallucinated Entities |
| ATLAS | AML.T0061 | LLM Prompt Self-Replication |
| ATLAS | AML.T0062 | Discover LLM Hallucinations |
| ATLAS | AML.T0063 | Discover AI Model Outputs |
| ATLAS | AML.T0064 | Gather RAG-Indexed Targets |
| ATLAS | AML.T0065 | LLM Prompt Crafting |
| ATLAS | AML.T0066 | Retrieval Content Crafting |
| ATLAS | AML.T0067 | LLM Trusted Output Components Manipulation |
| ATLAS | AML.T0067.000 | Citations |
| ATLAS | AML.T0068 | LLM Prompt Obfuscation |
| ATLAS | AML.T0069 | Discover LLM System Information |
| ATLAS | AML.T0069.000 | Special Character Sets |
| ATLAS | AML.T0069.001 | System Instruction Keywords |
| ATLAS | AML.T0069.002 | System Prompt |
| ATLAS | AML.T0070 | RAG Poisoning |
| ATLAS | AML.T0071 | False RAG Entry Injection |
| ATLAS | AML.T0072 | Reverse Shell |
| ATLAS | AML.T0073 | Impersonation |
| ATLAS | AML.T0074 | Masquerading |
| ATLAS | AML.T0075 | Cloud Service Discovery |
| ATLAS | AML.T0076 | Corrupt AI Model |
| ATLAS | AML.T0077 | LLM Response Rendering |
| ATLAS | AML.T0078 | Drive-by Compromise |
| ATLAS | AML.T0079 | Stage Capabilities |
| ATLAS | AML.T0080 | AI Agent Context Poisoning |
| ATLAS | AML.T0080.000 | Memory |
| ATLAS | AML.T0080.001 | Thread |
| ATLAS | AML.T0081 | Modify AI Agent Configuration |
| ATLAS | AML.T0082 | RAG Credential Harvesting |
| ATLAS | AML.T0083 | Credentials from AI Agent Configuration |
| ATLAS | AML.T0084 | Discover AI Agent Configuration |
| ATLAS | AML.T0084.000 | Embedded Knowledge |
| ATLAS | AML.T0084.001 | Tool Definitions |
| ATLAS | AML.T0084.002 | Activation Triggers |
| ATLAS | AML.T0084.003 | Call Chains |
| ATLAS | AML.T0085 | Data from AI Services |
| ATLAS | AML.T0085.000 | RAG Databases |
| ATLAS | AML.T0085.001 | AI Agent Tools |
| ATLAS | AML.T0086 | Exfiltration via AI Agent Tool Invocation |
| ATLAS | AML.T0087 | Gather Victim Identity Information |
| ATLAS | AML.T0088 | Generate Deepfakes |
| ATLAS | AML.T0089 | Process Discovery |
| ATLAS | AML.T0090 | OS Credential Dumping |
| ATLAS | AML.T0091 | Use Alternate Authentication Material |
| ATLAS | AML.T0091.000 | Application Access Token |
| ATLAS | AML.T0091.001 | Web Session Cookie |
| ATLAS | AML.T0092 | Manipulate User LLM Chat History |
| ATLAS | AML.T0093 | Prompt Infiltration via Public-Facing Application |
| ATLAS | AML.T0094 | Delay Execution of LLM Instructions |
| ATLAS | AML.T0095 | Search Open Websites/Domains |
| ATLAS | AML.T0095.000 | Code Repositories |
| ATLAS | AML.T0096 | AI Service API |
| ATLAS | AML.T0097 | Virtualization/Sandbox Evasion |
| ATLAS | AML.T0098 | AI Agent Tool Credential Harvesting |
| ATLAS | AML.T0099 | AI Agent Tool Data Poisoning |
| ATLAS | AML.T0100 | AI Agent Clickbait |
| ATLAS | AML.T0101 | Data Destruction via AI Agent Tool Invocation |
| ATLAS | AML.T0102 | Generate Malicious Commands |
| ATLAS | AML.T0103 | Deploy AI Agent |
| ATLAS | AML.T0104 | Publish Poisoned AI Agent Tool |
| ATLAS | AML.T0105 | Escape to Host |
| ATLAS | AML.T0106 | Exploitation for Credential Access |
| ATLAS | AML.T0107 | Exploitation for Defense Evasion |
| ATLAS | AML.T0108 | AI Agent |
| ATLAS | AML.T0109 | AI Supply Chain Rug Pull |
| ATLAS | AML.T0110 | AI Agent Tool Poisoning |
| ATLAS | AML.T0111 | AI Supply Chain Reputation Inflation |
| ATLAS | AML.T0112 | Machine Compromise |
| ATLAS | AML.T0112.000 | Local AI Agent |
| ATLAS | AML.T0112.001 | AI Artifacts |
| ATLAS | AML.T0113 | Steal Web Session Cookie |
| ATLAS | AML.T0114 | AI Service Web Interface |
| SPARTA | DE-0001 | Disable Fault Management |
| SPARTA | DE-0002 | Disrupt or Deceive Downlink |
| SPARTA | DE-0002.01 | Inhibit Ground System Functionality |
| SPARTA | DE-0002.02 | Jam Link Signal |
| SPARTA | DE-0002.03 | Inhibit Spacecraft Functionality |
| SPARTA | DE-0003 | On-Board Values Obfuscation |
| SPARTA | DE-0003.01 | Vehicle Command Counter (VCC) |
| SPARTA | DE-0003.02 | Rejected Command Counter |
| SPARTA | DE-0003.03 | Command Receiver On/Off Mode |
| SPARTA | DE-0003.04 | Command Receivers Received Signal Strength |
| SPARTA | DE-0003.05 | Command Receiver Lock Modes |
| SPARTA | DE-0003.06 | Telemetry Downlink Modes |
| SPARTA | DE-0003.07 | Cryptographic Modes |
| SPARTA | DE-0003.08 | Received Commands |
| SPARTA | DE-0003.09 | System Clock for Evasion |
| SPARTA | DE-0003.10 | GPS Ephemeris |
| SPARTA | DE-0003.11 | Watchdog Timer (WDT) for Evasion |
| SPARTA | DE-0003.12 | Poison AI/ML Training for Evasion |
| SPARTA | DE-0004 | Masquerading |
| SPARTA | DE-0005 | Subvert Protections via Safe-Mode |
| SPARTA | DE-0006 | Modify Whitelist |
| SPARTA | DE-0007 | Evasion via Rootkit |
| SPARTA | DE-0008 | Evasion via Bootkit |
| SPARTA | DE-0009 | Camouflage, Concealment, and Decoys (CCD) |
| SPARTA | DE-0009.01 | Debris Field |
| SPARTA | DE-0009.02 | Space Weather |
| SPARTA | DE-0009.03 | Trigger Premature Intercept |
| SPARTA | DE-0009.04 | Targeted Deception of Onboard SSA/SDA Sensors |
| SPARTA | DE-0009.05 | Corruption or Overload of Ground-Based SDA Systems |
| SPARTA | DE-0010 | Overflow Audit Log |
| SPARTA | DE-0011 | Credentialed Evasion |
| SPARTA | DE-0012 | Component Collusion |
| SPARTA | EX-0001 | Replay |
| SPARTA | EX-0001.01 | Command Packets |
| SPARTA | EX-0001.02 | Bus Traffic Replay |
| SPARTA | EX-0002 | Position, Navigation, and Timing (PNT) Geofencing |
| SPARTA | EX-0003 | Modify Authentication Process |
| SPARTA | EX-0004 | Compromise Boot Memory |
| SPARTA | EX-0005 | Exploit Hardware/Firmware Corruption |
| SPARTA | EX-0005.01 | Design Flaws |
| SPARTA | EX-0005.02 | Malicious Use of Hardware Commands |
| SPARTA | EX-0006 | Disable/Bypass Encryption |
| SPARTA | EX-0007 | Trigger Single Event Upset |
| SPARTA | EX-0008 | Time Synchronized Execution |
| SPARTA | EX-0008.01 | Absolute Time Sequences |
| SPARTA | EX-0008.02 | Relative Time Sequences |
| SPARTA | EX-0009 | Exploit Code Flaws |
| SPARTA | EX-0009.01 | Flight Software |
| SPARTA | EX-0009.02 | Operating System |
| SPARTA | EX-0009.03 | Known Vulnerability (COTS/FOSS) |
| SPARTA | EX-0010 | Malicious Code |
| SPARTA | EX-0010.01 | Ransomware |
| SPARTA | EX-0010.02 | Wiper Malware |
| SPARTA | EX-0010.03 | Rootkit |
| SPARTA | EX-0010.04 | Bootkit |
| SPARTA | EX-0011 | Exploit Reduced Protections During Safe-Mode |
| SPARTA | EX-0012 | Modify On-Board Values |
| SPARTA | EX-0012.01 | Registers |
| SPARTA | EX-0012.02 | Internal Routing Tables |
| SPARTA | EX-0012.03 | Memory Write/Loads |
| SPARTA | EX-0012.04 | App/Subscriber Tables |
| SPARTA | EX-0012.05 | Scheduling Algorithm |
| SPARTA | EX-0012.06 | Science/Payload Data |
| SPARTA | EX-0012.07 | Propulsion Subsystem |
| SPARTA | EX-0012.08 | Attitude Determination & Control Subsystem |
| SPARTA | EX-0012.09 | Electrical Power Subsystem |
| SPARTA | EX-0012.10 | Command & Data Handling Subsystem |
| SPARTA | EX-0012.11 | Watchdog Timer (WDT) |
| SPARTA | EX-0012.12 | System Clock |
| SPARTA | EX-0012.13 | Poison AI/ML Training Data |
| SPARTA | EX-0013 | Flooding |
| SPARTA | EX-0013.01 | Valid Commands |
| SPARTA | EX-0013.02 | Erroneous Input |
| SPARTA | EX-0014 | Spoofing |
| SPARTA | EX-0014.01 | Time Spoof |
| SPARTA | EX-0014.02 | Bus Traffic Spoofing |
| SPARTA | EX-0014.03 | Sensor Data |
| SPARTA | EX-0014.04 | Position, Navigation, and Timing (PNT) Spoofing |
| SPARTA | EX-0014.05 | Ballistic Missile Spoof |
| SPARTA | EX-0015 | Side-Channel Attack |
| SPARTA | EX-0016 | Jamming |
| SPARTA | EX-0016.01 | Uplink Jamming |
| SPARTA | EX-0016.02 | Downlink Jamming |
| SPARTA | EX-0016.03 | Position, Navigation, and Timing (PNT) Jamming |
| SPARTA | EX-0017 | Kinetic Physical Attack |
| SPARTA | EX-0017.01 | Direct Ascent ASAT |
| SPARTA | EX-0017.02 | Co-Orbital ASAT |
| SPARTA | EX-0018 | Non-Kinetic Physical Attack |
| SPARTA | EX-0018.01 | Electromagnetic Pulse (EMP) |
| SPARTA | EX-0018.02 | High-Powered Laser |
| SPARTA | EX-0018.03 | High-Powered Microwave |
| SPARTA | EXF-0001 | Replay |
| SPARTA | EXF-0002 | Side-Channel Exfiltration |
| SPARTA | EXF-0002.01 | Power Analysis Attacks |
| SPARTA | EXF-0002.02 | Electromagnetic Leakage Attacks |
| SPARTA | EXF-0002.03 | Traffic Analysis Attacks |
| SPARTA | EXF-0002.04 | Timing Attacks |
| SPARTA | EXF-0002.05 | Thermal Imaging attacks |
| SPARTA | EXF-0003 | Signal Interception |
| SPARTA | EXF-0003.01 | Uplink Exfiltration |
| SPARTA | EXF-0003.02 | Downlink Exfiltration |
| SPARTA | EXF-0004 | Out-of-Band Communications Link |
| SPARTA | EXF-0005 | Proximity Operations |
| SPARTA | EXF-0006 | Modify Communications Configuration |
| SPARTA | EXF-0006.01 | Software Defined Radio |
| SPARTA | EXF-0006.02 | Transponder |
| SPARTA | EXF-0007 | Compromised Ground System |
| SPARTA | EXF-0008 | Compromised Developer Site |
| SPARTA | EXF-0009 | Compromised Partner Site |
| SPARTA | EXF-0010 | Payload Communication Channel |
| SPARTA | IA-0001 | Compromise Supply Chain |
| SPARTA | IA-0001.01 | Software Dependencies & Development Tools |
| SPARTA | IA-0001.02 | Software Supply Chain |
| SPARTA | IA-0001.03 | Hardware Supply Chain |
| SPARTA | IA-0002 | Compromise Software Defined Radio |
| SPARTA | IA-0003 | Crosslink via Compromised Neighbor |
| SPARTA | IA-0004 | Secondary/Backup Communication Channel |
| SPARTA | IA-0004.01 | Ground Station |
| SPARTA | IA-0004.02 | Receiver |
| SPARTA | IA-0005 | Rendezvous & Proximity Operations |
| SPARTA | IA-0005.01 | Compromise Emanations |
| SPARTA | IA-0005.02 | Docked Vehicle / OSAM |
| SPARTA | IA-0005.03 | Proximity Grappling |
| SPARTA | IA-0006 | Compromise Hosted Payload |
| SPARTA | IA-0007 | Compromise Ground System |
| SPARTA | IA-0007.01 | Compromise On-Orbit Update |
| SPARTA | IA-0007.02 | Malicious Commanding via Valid GS |
| SPARTA | IA-0008 | Rogue External Entity |
| SPARTA | IA-0008.01 | Rogue Ground Station |
| SPARTA | IA-0008.02 | Rogue Spacecraft |
| SPARTA | IA-0008.03 | ASAT/Counterspace Weapon |
| SPARTA | IA-0009 | Trusted Relationship |
| SPARTA | IA-0009.01 | Mission Collaborator (academia, international, etc.) |
| SPARTA | IA-0009.02 | Vendor |
| SPARTA | IA-0009.03 | User Segment |
| SPARTA | IA-0010 | Unauthorized Access During Safe-Mode |
| SPARTA | IA-0011 | Auxiliary Device Compromise |
| SPARTA | IA-0012 | Assembly, Test, and Launch Operation Compromise |
| SPARTA | IA-0013 | Compromise Host Spacecraft |
| SPARTA | IMP-0001 | Deception (or Misdirection) |
| SPARTA | IMP-0002 | Disruption |
| SPARTA | IMP-0003 | Denial |
| SPARTA | IMP-0004 | Degradation |
| SPARTA | IMP-0005 | Destruction |
| SPARTA | IMP-0006 | Theft |
| SPARTA | LM-0001 | Hosted Payload |
| SPARTA | LM-0002 | Exploit Lack of Bus Segregation |
| SPARTA | LM-0003 | Constellation Hopping via Crosslink |
| SPARTA | LM-0004 | Visiting Vehicle Interface(s) |
| SPARTA | LM-0005 | Virtualization Escape |
| SPARTA | LM-0006 | Launch Vehicle Interface |
| SPARTA | LM-0006.01 | Rideshare Payload |
| SPARTA | LM-0007 | Credentialed Traversal |
| SPARTA | PER-0001 | Memory Compromise |
| SPARTA | PER-0002 | Backdoor |
| SPARTA | PER-0002.01 | Hardware Backdoor |
| SPARTA | PER-0002.02 | Software Backdoor |
| SPARTA | PER-0003 | Ground System Presence |
| SPARTA | PER-0004 | Replace Cryptographic Keys |
| SPARTA | PER-0005 | Credentialed Persistence |
| SPARTA | RD-0001 | Acquire Infrastructure |
| SPARTA | RD-0001.01 | Ground Station Equipment |
| SPARTA | RD-0001.02 | Commercial Ground Station Services |
| SPARTA | RD-0001.03 | Spacecraft |
| SPARTA | RD-0001.04 | Launch Facility |
| SPARTA | RD-0002 | Compromise Infrastructure |
| SPARTA | RD-0002.01 | Mission-Operated Ground System |
| SPARTA | RD-0002.02 | 3rd Party Ground System |
| SPARTA | RD-0002.03 | 3rd-Party Spacecraft |
| SPARTA | RD-0003 | Obtain Cyber Capabilities |
| SPARTA | RD-0003.01 | Exploit/Payload |
| SPARTA | RD-0003.02 | Cryptographic Keys |
| SPARTA | RD-0004 | Stage Capabilities |
| SPARTA | RD-0004.01 | Identify/Select Delivery Mechanism |
| SPARTA | RD-0004.02 | Upload Exploit/Payload |
| SPARTA | RD-0005 | Obtain Non-Cyber Capabilities |
| SPARTA | RD-0005.01 | Launch Services |
| SPARTA | RD-0005.02 | Non-Kinetic Physical ASAT |
| SPARTA | RD-0005.03 | Kinetic Physical ASAT |
| SPARTA | RD-0005.04 | Electronic ASAT |
| SPARTA | REC-0001 | Gather Spacecraft Design Information |
| SPARTA | REC-0001.01 | Software Design |
| SPARTA | REC-0001.02 | Firmware |
| SPARTA | REC-0001.03 | Cryptographic Algorithms |
| SPARTA | REC-0001.04 | Data Bus |
| SPARTA | REC-0001.05 | Thermal Control System |
| SPARTA | REC-0001.06 | Maneuver & Control |
| SPARTA | REC-0001.07 | Payload |
| SPARTA | REC-0001.08 | Power |
| SPARTA | REC-0001.09 | Fault Management |
| SPARTA | REC-0002 | Gather Spacecraft Descriptors |
| SPARTA | REC-0002.01 | Identifiers |
| SPARTA | REC-0002.02 | Organization |
| SPARTA | REC-0002.03 | Operations |
| SPARTA | REC-0003 | Gather Spacecraft Communications Information |
| SPARTA | REC-0003.01 | Communications Equipment |
| SPARTA | REC-0003.02 | Commanding Details |
| SPARTA | REC-0003.03 | Mission-Specific Channel Scanning |
| SPARTA | REC-0003.04 | Valid Credentials |
| SPARTA | REC-0004 | Gather Launch Information |
| SPARTA | REC-0004.01 | Flight Termination |
| SPARTA | REC-0005 | Eavesdropping |
| SPARTA | REC-0005.01 | Uplink Intercept Eavesdropping |
| SPARTA | REC-0005.02 | Downlink Intercept |
| SPARTA | REC-0005.03 | Proximity Operations |
| SPARTA | REC-0005.04 | Active Scanning (RF/Optical) |
| SPARTA | REC-0006 | Gather FSW Development Information |
| SPARTA | REC-0006.01 | Development Environment |
| SPARTA | REC-0006.02 | Security Testing Tools |
| SPARTA | REC-0007 | Monitor for Safe-Mode Indicators |
| SPARTA | REC-0008 | Gather Supply Chain Information |
| SPARTA | REC-0008.01 | Hardware Recon |
| SPARTA | REC-0008.02 | Software Recon |
| SPARTA | REC-0008.03 | Known Vulnerabilities |
| SPARTA | REC-0008.04 | Business Relationships |
| SPARTA | REC-0009 | Gather Mission Information |
| ICS | T0800 | Activate Firmware Update Mode |
| ICS | T0801 | Monitor Process State |
| ICS | T0802 | Automated Collection |
| ICS | T0803 | Block Command Message |
| ICS | T0804 | Block Reporting Message |
| ICS | T0805 | Block Serial COM |
| ICS | T0806 | Brute Force I/O |
| ICS | T0807 | Command-Line Interface |
| ICS | T0808 | Control Device Identification |
| ICS | T0809 | Data Destruction |
| ICS | T0810 | Data Historian Compromise |
| ICS | T0811 | Data from Information Repositories |
| ICS | T0812 | Default Credentials |
| ICS | T0813 | Denial of Control |
| ICS | T0814 | Denial of Service |
| ICS | T0815 | Denial of View |
| ICS | T0816 | Device Restart/Shutdown |
| ICS | T0817 | Drive-by Compromise |
| ICS | T0818 | Engineering Workstation Compromise |
| ICS | T0819 | Exploit Public-Facing Application |
| ICS | T0820 | Exploitation for Evasion |
| ICS | T0821 | Modify controller Tasking |
| ICS | T0822 | External Remote Services |
| ICS | T0823 | Graphical User Interface |
| ICS | T0824 | I/O Module Discovery |
| ICS | T0825 | Location Identification |
| ICS | T0826 | Loss of Availability |
| ICS | T0827 | Loss of Control |
| ICS | T0828 | Loss of Productivity and Revenue |
| ICS | T0829 | Loss of View |
| ICS | T0830 | Adversary-in-the-Middle |
| ICS | T0831 | Manipulation of Control |
| ICS | T0832 | Manipulation of View |
| ICS | T0833 | Modify Control Logic |
| ICS | T0834 | Native API |
| ICS | T0835 | Manipulate I/O Image |
| ICS | T0836 | Modify Parameter |
| ICS | T0837 | Loss of Protection |
| ICS | T0838 | Modify Alarm Settings |
| ICS | T0839 | Module Firmware |
| ICS | T0840 | Network Connection Enumeration |
| ICS | T0841 | Network Service Scanning |
| ICS | T0842 | Network Sniffing |
| ICS | T0843 | Program Download |
| ICS | T0843.001 | Download All |
| ICS | T0843.002 | Online Edit |
| ICS | T0843.003 | Program Append |
| ICS | T0844 | Program Organization Units |
| ICS | T0845 | Program Upload |
| ICS | T0846 | Remote System Discovery |
| ICS | T0846.001 | Port Scan |
| ICS | T0846.002 | Broadcast Discovery |
| ICS | T0846.003 | Multicast Discovery |
| ICS | T0847 | Replication Through Removable Media |
| ICS | T0848 | Rogue Master |
| ICS | T0849 | Masquerading |
| ICS | T0850 | Role Identification |
| ICS | T0851 | Rootkit |
| ICS | T0852 | Screen Capture |
| ICS | T0853 | Scripting |
| ICS | T0854 | Serial Connection Enumeration |
| ICS | T0855 | Unauthorized Command Message |
| ICS | T0856 | Spoof Reporting Message |
| ICS | T0857 | System Firmware |
| ICS | T0858 | Change Operating Mode |
| ICS | T0859 | Valid Accounts |
| ICS | T0860 | Wireless Compromise |
| ICS | T0861 | Point & Tag Identification |
| ICS | T0862 | Supply Chain Compromise |
| ICS | T0863 | User Execution |
| ICS | T0864 | Transient Cyber Asset |
| ICS | T0865 | Spearphishing Attachment |
| ICS | T0866 | Exploitation of Remote Services |
| ICS | T0867 | Lateral Tool Transfer |
| ICS | T0868 | Detect Operating Mode |
| ICS | T0869 | Standard Application Layer Protocol |
| ICS | T0870 | Detect Program State |
| ICS | T0871 | Execution through API |
| ICS | T0872 | Indicator Removal on Host |
| ICS | T0873 | Project File Infection |
| ICS | T0873.001 | Siemens Project File Format |
| ICS | T0874 | Hooking |
| ICS | T0875 | Change Program State |
| ICS | T0877 | I/O Image |
| ICS | T0878 | Alarm Suppression |
| ICS | T0879 | Damage to Property |
| ICS | T0880 | Loss of Safety |
| ICS | T0881 | Service Stop |
| ICS | T0882 | Theft of Operational Information |
| ICS | T0883 | Internet Accessible Device |
| ICS | T0884 | Connection Proxy |
| ICS | T0885 | Commonly Used Port |
| ICS | T0886 | Remote Services |
| ICS | T0887 | Wireless Sniffing |
| ICS | T0888 | Remote System Information Discovery |
| ICS | T0889 | Modify Program |
| ICS | T0890 | Exploitation for Privilege Escalation |
| ICS | T0891 | Hardcoded Credentials |
| ICS | T0892 | Change Credential |
| ICS | T0893 | Data from Local System |
| ICS | T0894 | System Binary Proxy Execution |
| ICS | T0895 | Autorun Image |
| Enterprise | T1001 | Data Obfuscation |
| Enterprise | T1001.001 | Junk Data |
| Enterprise | T1001.002 | Steganography |
| Enterprise | T1001.003 | Protocol or Service Impersonation |
| Enterprise | T1002 | Data Compressed |
| Enterprise | T1003 | OS Credential Dumping |
| Enterprise | T1003.001 | LSASS Memory |
| Enterprise | T1003.002 | Security Account Manager |
| Enterprise | T1003.003 | NTDS |
| Enterprise | T1003.004 | LSA Secrets |
| Enterprise | T1003.005 | Cached Domain Credentials |
| Enterprise | T1003.006 | DCSync |
| Enterprise | T1003.007 | Proc Filesystem |
| Enterprise | T1003.008 | /etc/passwd and /etc/shadow |
| Enterprise | T1004 | Winlogon Helper DLL |
| Enterprise | T1005 | Data from Local System |
| Enterprise | T1006 | Direct Volume Access |
| Enterprise | T1007 | System Service Discovery |
| Enterprise | T1008 | Fallback Channels |
| Enterprise | T1009 | Binary Padding |
| Enterprise | T1010 | Application Window Discovery |
| Enterprise | T1011 | Exfiltration Over Other Network Medium |
| Enterprise | T1011.001 | Exfiltration Over Bluetooth |
| Enterprise | T1012 | Query Registry |
| Enterprise | T1013 | Port Monitors |
| Enterprise | T1014 | Rootkit |
| Enterprise | T1015 | Accessibility Features |
| Enterprise | T1016 | System Network Configuration Discovery |
| Enterprise | T1016.001 | Internet Connection Discovery |
| Enterprise | T1016.002 | Wi-Fi Discovery |
| Enterprise | T1017 | Application Deployment Software |
| Enterprise | T1018 | Remote System Discovery |
| Enterprise | T1019 | System Firmware |
| Enterprise | T1020 | Automated Exfiltration |
| Enterprise | T1020.001 | Traffic Duplication |
| Enterprise | T1021 | Remote Services |
| Enterprise | T1021.001 | Remote Desktop Protocol |
| Enterprise | T1021.002 | SMB/Windows Admin Shares |
| Enterprise | T1021.003 | Distributed Component Object Model |
| Enterprise | T1021.004 | SSH |
| Enterprise | T1021.005 | VNC |
| Enterprise | T1021.006 | Windows Remote Management |
| Enterprise | T1021.007 | Cloud Services |
| Enterprise | T1021.008 | Direct Cloud VM Connections |
| Enterprise | T1022 | Data Encrypted |
| Enterprise | T1023 | Shortcut Modification |
| Enterprise | T1024 | Custom Cryptographic Protocol |
| Enterprise | T1025 | Data from Removable Media |
| Enterprise | T1026 | Multiband Communication |
| Enterprise | T1027 | Obfuscated Files or Information |
| Enterprise | T1027.001 | Binary Padding |
| Enterprise | T1027.002 | Software Packing |
| Enterprise | T1027.003 | Steganography |
| Enterprise | T1027.004 | Compile After Delivery |
| Enterprise | T1027.005 | Indicator Removal from Tools |
| Enterprise | T1027.006 | HTML Smuggling |
| Enterprise | T1027.007 | Dynamic API Resolution |
| Enterprise | T1027.008 | Stripped Payloads |
| Enterprise | T1027.009 | Embedded Payloads |
| Enterprise | T1027.010 | Command Obfuscation |
| Enterprise | T1027.011 | Fileless Storage |
| Enterprise | T1027.012 | LNK Icon Smuggling |
| Enterprise | T1027.013 | Encrypted/Encoded File |
| Enterprise | T1027.014 | Polymorphic Code |
| Enterprise | T1027.015 | Compression |
| Enterprise | T1027.016 | Junk Code Insertion |
| Enterprise | T1027.017 | SVG Smuggling |
| Enterprise | T1027.018 | Invisible Unicode |
| Enterprise | T1028 | Windows Remote Management |
| Enterprise | T1029 | Scheduled Transfer |
| Enterprise | T1030 | Data Transfer Size Limits |
| Enterprise | T1031 | Modify Existing Service |
| Enterprise | T1032 | Standard Cryptographic Protocol |
| Enterprise | T1033 | System Owner/User Discovery |
| Enterprise | T1034 | Path Interception |
| Enterprise | T1035 | Service Execution |
| Enterprise | T1036 | Masquerading |
| Enterprise | T1036.001 | Invalid Code Signature |
| Enterprise | T1036.002 | Right-to-Left Override |
| Enterprise | T1036.003 | Rename Legitimate Utilities |
| Enterprise | T1036.004 | Masquerade Task or Service |
| Enterprise | T1036.005 | Match Legitimate Resource Name or Location |
| Enterprise | T1036.006 | Space after Filename |
| Enterprise | T1036.007 | Double File Extension |
| Enterprise | T1036.008 | Masquerade File Type |
| Enterprise | T1036.009 | Break Process Trees |
| Enterprise | T1036.010 | Masquerade Account Name |
| Enterprise | T1036.011 | Overwrite Process Arguments |
| Enterprise | T1036.012 | Browser Fingerprint |
| Enterprise | T1037 | Boot or Logon Initialization Scripts |
| Enterprise | T1037.001 | Logon Script (Windows) |
| Enterprise | T1037.002 | Login Hook |
| Enterprise | T1037.003 | Network Logon Script |
| Enterprise | T1037.004 | RC Scripts |
| Enterprise | T1037.005 | Startup Items |
| Enterprise | T1038 | DLL Search Order Hijacking |
| Enterprise | T1039 | Data from Network Shared Drive |
| Enterprise | T1040 | Network Sniffing |
| Enterprise | T1041 | Exfiltration Over C2 Channel |
| Enterprise | T1042 | Change Default File Association |
| Enterprise | T1043 | Commonly Used Port |
| Enterprise | T1044 | File System Permissions Weakness |
| Enterprise | T1045 | Software Packing |
| Enterprise | T1046 | Network Service Discovery |
| Enterprise | T1047 | Windows Management Instrumentation |
| Enterprise | T1048 | Exfiltration Over Alternative Protocol |
| Enterprise | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
| Enterprise | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
| Enterprise | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
| Enterprise | T1049 | System Network Connections Discovery |
| Enterprise | T1050 | New Service |
| Enterprise | T1051 | Shared Webroot |
| Enterprise | T1052 | Exfiltration Over Physical Medium |
| Enterprise | T1052.001 | Exfiltration over USB |
| Enterprise | T1053 | Scheduled Task/Job |
| Enterprise | T1053.001 | At (Linux) Execution |
| Enterprise | T1053.002 | At |
| Enterprise | T1053.003 | Cron |
| Enterprise | T1053.004 | Launchd |
| Enterprise | T1053.005 | Scheduled Task |
| Enterprise | T1053.006 | Systemd Timers |
| Enterprise | T1053.007 | Container Orchestration Job |
| Enterprise | T1054 | Indicator Blocking |
| Enterprise | T1055 | Process Injection |
| Enterprise | T1055.001 | Dynamic-link Library Injection |
| Enterprise | T1055.002 | Portable Executable Injection |
| Enterprise | T1055.003 | Thread Execution Hijacking |
| Enterprise | T1055.004 | Asynchronous Procedure Call |
| Enterprise | T1055.005 | Thread Local Storage |
| Enterprise | T1055.008 | Ptrace System Calls |
| Enterprise | T1055.009 | Proc Memory |
| Enterprise | T1055.011 | Extra Window Memory Injection |
| Enterprise | T1055.012 | Process Hollowing |
| Enterprise | T1055.013 | Process Doppelgänging |
| Enterprise | T1055.014 | VDSO Hijacking |
| Enterprise | T1055.015 | ListPlanting |
| Enterprise | T1056 | Input Capture |
| Enterprise | T1056.001 | Keylogging |
| Enterprise | T1056.002 | GUI Input Capture |
| Enterprise | T1056.003 | Web Portal Capture |
| Enterprise | T1056.004 | Credential API Hooking |
| Enterprise | T1057 | Process Discovery |
| Enterprise | T1058 | Service Registry Permissions Weakness |
| Enterprise | T1059 | Command and Scripting Interpreter |
| Enterprise | T1059.001 | PowerShell |
| Enterprise | T1059.002 | AppleScript |
| Enterprise | T1059.003 | Windows Command Shell |
| Enterprise | T1059.004 | Unix Shell |
| Enterprise | T1059.005 | Visual Basic |
| Enterprise | T1059.006 | Python |
| Enterprise | T1059.007 | JavaScript |
| Enterprise | T1059.008 | Network Device CLI |
| Enterprise | T1059.009 | Cloud API |
| Enterprise | T1059.010 | AutoHotKey & AutoIT |
| Enterprise | T1059.011 | Lua |
| Enterprise | T1059.012 | Hypervisor CLI |
| Enterprise | T1059.013 | Container CLI/API |
| Enterprise | T1060 | Registry Run Keys / Startup Folder |
| Enterprise | T1061 | Graphical User Interface |
| Enterprise | T1062 | Hypervisor |
| Enterprise | T1063 | Security Software Discovery |
| Enterprise | T1064 | Scripting |
| Enterprise | T1065 | Uncommonly Used Port |
| Enterprise | T1066 | Indicator Removal from Tools |
| Enterprise | T1067 | Bootkit |
| Enterprise | T1068 | Exploitation for Privilege Escalation |
| Enterprise | T1069 | Permission Groups Discovery |
| Enterprise | T1069.001 | Local Groups |
| Enterprise | T1069.002 | Domain Groups |
| Enterprise | T1069.003 | Cloud Groups |
| Enterprise | T1070 | Indicator Removal |
| Enterprise | T1070.001 | Clear Windows Event Logs |
| Enterprise | T1070.002 | Clear Linux or Mac System Logs |
| Enterprise | T1070.003 | Clear Command History |
| Enterprise | T1070.004 | File Deletion |
| Enterprise | T1070.005 | Network Share Connection Removal |
| Enterprise | T1070.006 | Timestomp |
| Enterprise | T1070.007 | Clear Network Connection History and Configurations |
| Enterprise | T1070.008 | Clear Mailbox Data |
| Enterprise | T1070.009 | Clear Persistence |
| Enterprise | T1070.010 | Relocate Malware |
| Enterprise | T1071 | Application Layer Protocol |
| Enterprise | T1071.001 | Web Protocols |
| Enterprise | T1071.002 | File Transfer Protocols |
| Enterprise | T1071.003 | Mail Protocols |
| Enterprise | T1071.004 | DNS |
| Enterprise | T1071.005 | Publish/Subscribe Protocols |
| Enterprise | T1072 | Software Deployment Tools |
| Enterprise | T1073 | DLL Side-Loading |
| Enterprise | T1074 | Data Staged |
| Enterprise | T1074.001 | Local Data Staging |
| Enterprise | T1074.002 | Remote Data Staging |
| Enterprise | T1075 | Pass the Hash |
| Enterprise | T1076 | Remote Desktop Protocol |
| Enterprise | T1077 | Windows Admin Shares |
| Enterprise | T1078 | Valid Accounts |
| Enterprise | T1078.001 | Default Accounts |
| Enterprise | T1078.002 | Domain Accounts |
| Enterprise | T1078.003 | Local Accounts |
| Enterprise | T1078.004 | Cloud Accounts |
| Enterprise | T1079 | Multilayer Encryption |
| Enterprise | T1080 | Taint Shared Content |
| Enterprise | T1081 | Credentials in Files |
| Enterprise | T1082 | System Information Discovery |
| Enterprise | T1083 | File and Directory Discovery |
| Enterprise | T1084 | Windows Management Instrumentation Event Subscription |
| Enterprise | T1085 | Rundll32 |
| Enterprise | T1086 | PowerShell |
| Enterprise | T1087 | Account Discovery |
| Enterprise | T1087.001 | Local Account |
| Enterprise | T1087.002 | Domain Account |
| Enterprise | T1087.003 | Email Account |
| Enterprise | T1087.004 | Cloud Account |
| Enterprise | T1088 | Bypass User Account Control |
| Enterprise | T1089 | Disabling Security Tools |
| Enterprise | T1090 | Proxy |
| Enterprise | T1090.001 | Internal Proxy |
| Enterprise | T1090.002 | External Proxy |
| Enterprise | T1090.003 | Multi-hop Proxy |
| Enterprise | T1090.004 | Domain Fronting |
| Enterprise | T1091 | Replication Through Removable Media |
| Enterprise | T1092 | Communication Through Removable Media |
| Enterprise | T1093 | Process Hollowing |
| Enterprise | T1094 | Custom Command and Control Protocol |
| Enterprise | T1095 | Non-Application Layer Protocol |
| Enterprise | T1096 | NTFS File Attributes |
| Enterprise | T1097 | Pass the Ticket |
| Enterprise | T1098 | Account Manipulation |
| Enterprise | T1098.001 | Additional Cloud Credentials |
| Enterprise | T1098.002 | Additional Email Delegate Permissions |
| Enterprise | T1098.003 | Additional Cloud Roles |
| Enterprise | T1098.004 | SSH Authorized Keys |
| Enterprise | T1098.005 | Device Registration |
| Enterprise | T1098.006 | Additional Container Cluster Roles |
| Enterprise | T1098.007 | Additional Local or Domain Groups |
| Enterprise | T1099 | Timestomp |
| Enterprise | T1100 | Web Shell |
| Enterprise | T1101 | Security Support Provider |
| Enterprise | T1102 | Web Service |
| Enterprise | T1102.001 | Dead Drop Resolver |
| Enterprise | T1102.002 | Bidirectional Communication |
| Enterprise | T1102.003 | One-Way Communication |
| Enterprise | T1103 | AppInit DLLs |
| Enterprise | T1104 | Multi-Stage Channels |
| Enterprise | T1105 | Ingress Tool Transfer |
| Enterprise | T1106 | Native API |
| Enterprise | T1107 | File Deletion |
| Enterprise | T1108 | Redundant Access |
| Enterprise | T1109 | Component Firmware |
| Enterprise | T1110 | Brute Force |
| Enterprise | T1110.001 | Password Guessing |
| Enterprise | T1110.002 | Password Cracking |
| Enterprise | T1110.003 | Password Spraying |
| Enterprise | T1110.004 | Credential Stuffing |
| Enterprise | T1111 | Multi-Factor Authentication Interception |
| Enterprise | T1112 | Modify Registry |
| Enterprise | T1113 | Screen Capture |
| Enterprise | T1114 | Email Collection |
| Enterprise | T1114.001 | Local Email Collection |
| Enterprise | T1114.002 | Remote Email Collection |
| Enterprise | T1114.003 | Email Forwarding Rule |
| Enterprise | T1115 | Clipboard Data |
| Enterprise | T1116 | Code Signing |
| Enterprise | T1117 | Regsvr32 |
| Enterprise | T1118 | InstallUtil |
| Enterprise | T1119 | Automated Collection |
| Enterprise | T1120 | Peripheral Device Discovery |
| Enterprise | T1121 | Regsvcs/Regasm |
| Enterprise | T1122 | Component Object Model Hijacking |
| Enterprise | T1123 | Audio Capture |
| Enterprise | T1124 | System Time Discovery |
| Enterprise | T1125 | Video Capture |
| Enterprise | T1126 | Network Share Connection Removal |
| Enterprise | T1127 | Trusted Developer Utilities Proxy Execution |
| Enterprise | T1127.001 | MSBuild |
| Enterprise | T1127.002 | ClickOnce |
| Enterprise | T1127.003 | JamPlus |
| Enterprise | T1128 | Netsh Helper DLL |
| Enterprise | T1129 | Shared Modules |
| Enterprise | T1130 | Install Root Certificate |
| Enterprise | T1131 | Authentication Package |
| Enterprise | T1132 | Data Encoding |
| Enterprise | T1132.001 | Standard Encoding |
| Enterprise | T1132.002 | Non-Standard Encoding |
| Enterprise | T1133 | External Remote Services |
| Enterprise | T1134 | Access Token Manipulation |
| Enterprise | T1134.001 | Token Impersonation/Theft |
| Enterprise | T1134.002 | Create Process with Token |
| Enterprise | T1134.003 | Make and Impersonate Token |
| Enterprise | T1134.004 | Parent PID Spoofing |
| Enterprise | T1134.005 | SID-History Injection |
| Enterprise | T1135 | Network Share Discovery |
| Enterprise | T1136 | Create Account |
| Enterprise | T1136.001 | Local Account |
| Enterprise | T1136.002 | Domain Account |
| Enterprise | T1136.003 | Cloud Account |
| Enterprise | T1137 | Office Application Startup |
| Enterprise | T1137.001 | Office Template Macros |
| Enterprise | T1137.002 | Office Test |
| Enterprise | T1137.003 | Outlook Forms |
| Enterprise | T1137.004 | Outlook Home Page |
| Enterprise | T1137.005 | Outlook Rules |
| Enterprise | T1137.006 | Add-ins |
| Enterprise | T1138 | Application Shimming |
| Enterprise | T1139 | Bash History |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information |
| Enterprise | T1141 | Input Prompt |
| Enterprise | T1142 | Keychain |
| Enterprise | T1143 | Hidden Window |
| Enterprise | T1144 | Gatekeeper Bypass |
| Enterprise | T1145 | Private Keys |
| Enterprise | T1146 | Clear Command History |
| Enterprise | T1147 | Hidden Users |
| Enterprise | T1148 | HISTCONTROL |
| Enterprise | T1149 | LC_MAIN Hijacking |
| Enterprise | T1150 | Plist Modification |
| Enterprise | T1151 | Space after Filename |
| Enterprise | T1152 | Launchctl |
| Enterprise | T1153 | Source |
| Enterprise | T1154 | Trap |
| Enterprise | T1155 | AppleScript |
| Enterprise | T1156 | Malicious Shell Modification |
| Enterprise | T1157 | Dylib Hijacking |
| Enterprise | T1158 | Hidden Files and Directories |
| Enterprise | T1159 | Launch Agent |
| Enterprise | T1160 | Launch Daemon |
| Enterprise | T1161 | LC_LOAD_DYLIB Addition |
| Enterprise | T1162 | Login Item |
| Enterprise | T1163 | Rc.common |
| Enterprise | T1164 | Re-opened Applications |
| Enterprise | T1165 | Startup Items |
| Enterprise | T1166 | Setuid and Setgid |
| Enterprise | T1167 | Securityd Memory |
| Enterprise | T1168 | Local Job Scheduling |
| Enterprise | T1169 | Sudo |
| Enterprise | T1170 | Mshta |
| Enterprise | T1171 | LLMNR/NBT-NS Poisoning and Relay |
| Enterprise | T1172 | Domain Fronting |
| Enterprise | T1173 | Dynamic Data Exchange |
| Enterprise | T1174 | Password Filter DLL |
| Enterprise | T1175 | Component Object Model and Distributed COM |
| Enterprise | T1176 | Software Extensions |
| Enterprise | T1176.001 | Browser Extensions |
| Enterprise | T1176.002 | IDE Extensions |
| Enterprise | T1177 | LSASS Driver |
| Enterprise | T1178 | SID-History Injection |
| Enterprise | T1179 | Hooking |
| Enterprise | T1180 | Screensaver |
| Enterprise | T1181 | Extra Window Memory Injection |
| Enterprise | T1182 | AppCert DLLs |
| Enterprise | T1183 | Image File Execution Options Injection |
| Enterprise | T1184 | SSH Hijacking |
| Enterprise | T1185 | Browser Session Hijacking |
| Enterprise | T1186 | Process Doppelgänging |
| Enterprise | T1187 | Forced Authentication |
| Enterprise | T1188 | Multi-hop Proxy |
| Enterprise | T1189 | Drive-by Compromise |
| Enterprise | T1190 | Exploit Public-Facing Application |
| Enterprise | T1191 | CMSTP |
| Enterprise | T1192 | Spearphishing Link |
| Enterprise | T1193 | Spearphishing Attachment |
| Enterprise | T1194 | Spearphishing via Service |
| Enterprise | T1195 | Supply Chain Compromise |
| Enterprise | T1195.001 | Compromise Software Dependencies and Development Tools |
| Enterprise | T1195.002 | Compromise Software Supply Chain |
| Enterprise | T1195.003 | Compromise Hardware Supply Chain |
| Enterprise | T1196 | Control Panel Items |
| Enterprise | T1197 | BITS Jobs |
| Enterprise | T1198 | SIP and Trust Provider Hijacking |
| Enterprise | T1199 | Trusted Relationship |
| Enterprise | T1200 | Hardware Additions |
| Enterprise | T1201 | Password Policy Discovery |
| Enterprise | T1202 | Indirect Command Execution |
| Enterprise | T1203 | Exploitation for Client Execution |
| Enterprise | T1204 | User Execution |
| Enterprise | T1204.001 | Malicious Link |
| Enterprise | T1204.002 | Malicious File |
| Enterprise | T1204.003 | Malicious Image |
| Enterprise | T1204.004 | Malicious Copy and Paste |
| Enterprise | T1204.005 | Malicious Library |
| Enterprise | T1205 | Traffic Signaling |
| Enterprise | T1205.001 | Port Knocking |
| Enterprise | T1205.002 | Socket Filters |
| Enterprise | T1206 | Sudo Caching |
| Enterprise | T1207 | Rogue Domain Controller |
| Enterprise | T1208 | Kerberoasting |
| Enterprise | T1209 | Time Providers |
| Enterprise | T1210 | Exploitation of Remote Services |
| Enterprise | T1211 | Exploitation for Stealth |
| Enterprise | T1212 | Exploitation for Credential Access |
| Enterprise | T1213 | Data from Information Repositories |
| Enterprise | T1213.001 | Confluence |
| Enterprise | T1213.002 | Sharepoint |
| Enterprise | T1213.003 | Code Repositories |
| Enterprise | T1213.004 | Customer Relationship Management Software |
| Enterprise | T1213.005 | Messaging Applications |
| Enterprise | T1213.006 | Databases |
| Enterprise | T1214 | Credentials in Registry |
| Enterprise | T1215 | Kernel Modules and Extensions |
| Enterprise | T1216 | System Script Proxy Execution |
| Enterprise | T1216.001 | PubPrn |
| Enterprise | T1216.002 | SyncAppvPublishingServer |
| Enterprise | T1217 | Browser Information Discovery |
| Enterprise | T1218 | System Binary Proxy Execution |
| Enterprise | T1218.001 | Compiled HTML File |
| Enterprise | T1218.002 | Control Panel |
| Enterprise | T1218.003 | CMSTP |
| Enterprise | T1218.004 | InstallUtil |
| Enterprise | T1218.005 | Mshta |
| Enterprise | T1218.007 | Msiexec |
| Enterprise | T1218.008 | Odbcconf |
| Enterprise | T1218.009 | Regsvcs/Regasm |
| Enterprise | T1218.010 | Regsvr32 |
| Enterprise | T1218.011 | Rundll32 |
| Enterprise | T1218.012 | Verclsid |
| Enterprise | T1218.013 | Mavinject |
| Enterprise | T1218.014 | MMC |
| Enterprise | T1218.015 | Electron Applications |
| Enterprise | T1219 | Remote Access Tools |
| Enterprise | T1219.001 | IDE Tunneling |
| Enterprise | T1219.002 | Remote Desktop Software |
| Enterprise | T1219.003 | Remote Access Hardware |
| Enterprise | T1220 | XSL Script Processing |
| Enterprise | T1221 | Template Injection |
| Enterprise | T1222 | File and Directory Permissions Modification |
| Enterprise | T1222.001 | Windows Permissions |
| Enterprise | T1222.002 | Linux and Mac Permissions |
| Enterprise | T1223 | Compiled HTML File |
| Mobile | T1398 | Boot or Logon Initialization Scripts |
| Mobile | T1399 | Modify Trusted Execution Environment |
| Mobile | T1400 | Modify System Partition |
| Mobile | T1401 | Device Administrator Permissions |
| Mobile | T1402 | Broadcast Receivers |
| Mobile | T1403 | Modify Cached Executable Code |
| Mobile | T1404 | Exploitation for Privilege Escalation |
| Mobile | T1405 | Exploit TEE Vulnerability |
| Mobile | T1406 | Obfuscated Files or Information |
| Mobile | T1406.001 | Steganography |
| Mobile | T1406.002 | Software Packing |
| Mobile | T1407 | Download New Code at Runtime |
| Mobile | T1408 | Disguise Root/Jailbreak Indicators |
| Mobile | T1409 | Stored Application Data |
| Mobile | T1410 | Network Traffic Capture or Redirection |
| Mobile | T1411 | Input Prompt |
| Mobile | T1412 | Capture SMS Messages |
| Mobile | T1413 | Access Sensitive Data in Device Logs |
| Mobile | T1414 | Clipboard Data |
| Mobile | T1415 | URL Scheme Hijacking |
| Mobile | T1416 | URI Hijacking |
| Mobile | T1417 | Input Capture |
| Mobile | T1417.001 | Keylogging |
| Mobile | T1417.002 | GUI Input Capture |
| Mobile | T1418 | Software Discovery |
| Mobile | T1418.001 | Security Software Discovery |
| Mobile | T1419 | Device Type Discovery |
| Mobile | T1420 | File and Directory Discovery |
| Mobile | T1421 | System Network Connections Discovery |
| Mobile | T1422 | System Network Configuration Discovery |
| Mobile | T1422.001 | Internet Connection Discovery |
| Mobile | T1422.002 | Wi-Fi Discovery |
| Mobile | T1423 | Network Service Scanning |
| Mobile | T1424 | Process Discovery |
| Mobile | T1426 | System Information Discovery |
| Mobile | T1427 | Attack PC via USB Connection |
| Mobile | T1428 | Exploitation of Remote Services |
| Mobile | T1429 | Audio Capture |
| Mobile | T1430 | Location Tracking |
| Mobile | T1430.001 | Remote Device Management Services |
| Mobile | T1430.002 | Impersonate SS7 Nodes |
| Mobile | T1432 | Access Contact List |
| Mobile | T1433 | Access Call Log |
| Mobile | T1435 | Access Calendar Entries |
| Mobile | T1436 | Commonly Used Port |
| Mobile | T1437 | Application Layer Protocol |
| Mobile | T1437.001 | Web Protocols |
| Mobile | T1438 | Exfiltration Over Other Network Medium |
| Mobile | T1444 | Masquerade as Legitimate Application |
| Mobile | T1446 | Device Lockout |
| Mobile | T1447 | Delete Device Data |
| Mobile | T1448 | Carrier Billing Fraud |
| Mobile | T1451 | SIM Card Swap |
| Mobile | T1452 | Manipulate App Store Rankings or Ratings |
| Mobile | T1453 | Abuse Accessibility Features |
| Mobile | T1454 | Malicious SMS Message |
| Mobile | T1456 | Drive-By Compromise |
| Mobile | T1458 | Replication Through Removable Media |
| Mobile | T1461 | Lockscreen Bypass |
| Mobile | T1464 | Network Denial of Service |
| Mobile | T1471 | Data Encrypted for Impact |
| Mobile | T1472 | Generate Fraudulent Advertising Revenue |
| Mobile | T1474 | Supply Chain Compromise |
| Mobile | T1474.001 | Compromise Software Dependencies and Development Tools |
| Mobile | T1474.002 | Compromise Hardware Supply Chain |
| Mobile | T1474.003 | Compromise Software Supply Chain |
| Mobile | T1475 | Deliver Malicious App via Authorized App Store |
| Mobile | T1476 | Deliver Malicious App via Other Means |
| Mobile | T1477 | Exploit via Radio Interfaces |
| Mobile | T1478 | Install Insecure or Malicious Configuration |
| Enterprise | T1480 | Execution Guardrails |
| Enterprise | T1480.001 | Environmental Keying |
| Enterprise | T1480.002 | Mutual Exclusion |
| Mobile | T1481 | Web Service |
| Mobile | T1481.001 | Dead Drop Resolver |
| Mobile | T1481.002 | Bidirectional Communication |
| Mobile | T1481.003 | One-Way Communication |
| Enterprise | T1482 | Domain Trust Discovery |
| Enterprise | T1483 | Domain Generation Algorithms |
| Enterprise | T1484 | Domain or Tenant Policy Modification |
| Enterprise | T1484.001 | Group Policy Modification |
| Enterprise | T1484.002 | Trust Modification |
| Enterprise | T1485 | Data Destruction |
| Enterprise | T1485.001 | Lifecycle-Triggered Deletion |
| Enterprise | T1486 | Data Encrypted for Impact |
| Enterprise | T1487 | Disk Structure Wipe |
| Enterprise | T1488 | Disk Content Wipe |
| Enterprise | T1489 | Service Stop |
| Enterprise | T1490 | Inhibit System Recovery |
| Enterprise | T1491 | Defacement |
| Enterprise | T1491.001 | Internal Defacement |
| Enterprise | T1491.002 | External Defacement |
| Enterprise | T1492 | Stored Data Manipulation |
| Enterprise | T1493 | Transmitted Data Manipulation |
| Enterprise | T1494 | Runtime Data Manipulation |
| Enterprise | T1495 | Firmware Corruption |
| Enterprise | T1496 | Resource Hijacking |
| Enterprise | T1496.001 | Compute Hijacking |
| Enterprise | T1496.002 | Bandwidth Hijacking |
| Enterprise | T1496.003 | SMS Pumping |
| Enterprise | T1496.004 | Cloud Service Hijacking |
| Enterprise | T1497 | Virtualization/Sandbox Evasion |
| Enterprise | T1497.001 | System Checks |
| Enterprise | T1497.002 | User Activity Based Checks |
| Enterprise | T1497.003 | Time Based Checks |
| Enterprise | T1498 | Network Denial of Service |
| Enterprise | T1498.001 | Direct Network Flood |
| Enterprise | T1498.002 | Reflection Amplification |
| Enterprise | T1499 | Endpoint Denial of Service |
| Enterprise | T1499.001 | OS Exhaustion Flood |
| Enterprise | T1499.002 | Service Exhaustion Flood |
| Enterprise | T1499.003 | Application Exhaustion Flood |
| Enterprise | T1499.004 | Application or System Exploitation |
| Enterprise | T1500 | Compile After Delivery |
| Enterprise | T1501 | Systemd Service |
| Enterprise | T1502 | Parent PID Spoofing |
| Enterprise | T1503 | Credentials from Web Browsers |
| Enterprise | T1504 | PowerShell Profile |
| Enterprise | T1505 | Server Software Component |
| Enterprise | T1505.001 | SQL Stored Procedures |
| Enterprise | T1505.002 | Transport Agent |
| Enterprise | T1505.003 | Web Shell |
| Enterprise | T1505.004 | IIS Components |
| Enterprise | T1505.005 | Terminal Services DLL |
| Enterprise | T1505.006 | vSphere Installation Bundles |
| Enterprise | T1506 | Web Session Cookie |
| Mobile | T1507 | Network Information Discovery |
| Mobile | T1508 | Suppress Application Icon |
| Mobile | T1509 | Non-Standard Port |
| Mobile | T1510 | Clipboard Modification |
| Mobile | T1512 | Video Capture |
| Mobile | T1513 | Screen Capture |
| Enterprise | T1514 | Elevated Execution with Prompt |
| Mobile | T1516 | Input Injection |
| Mobile | T1517 | Access Notifications |
| Enterprise | T1518 | Software Discovery |
| Enterprise | T1518.001 | Security Software Discovery |
| Enterprise | T1518.002 | Backup Software Discovery |
| Enterprise | T1519 | Emond |
| Mobile | T1520 | Domain Generation Algorithms |
| Mobile | T1521 | Encrypted Channel |
| Mobile | T1521.001 | Symmetric Cryptography |
| Mobile | T1521.002 | Asymmetric Cryptography |
| Mobile | T1521.003 | SSL Pinning |
| Enterprise | T1522 | Cloud Instance Metadata API |
| Mobile | T1523 | Evade Analysis Environment |
| Enterprise | T1525 | Implant Internal Image |
| Enterprise | T1526 | Cloud Service Discovery |
| Enterprise | T1527 | Application Access Token |
| Enterprise | T1528 | Steal Application Access Token |
| Enterprise | T1529 | System Shutdown/Reboot |
| Enterprise | T1530 | Data from Cloud Storage |
| Enterprise | T1531 | Account Access Removal |
| Mobile | T1532 | Archive Collected Data |
| Mobile | T1533 | Data from Local System |
| Enterprise | T1534 | Internal Spearphishing |
| Enterprise | T1535 | Unused/Unsupported Cloud Regions |
| Enterprise | T1536 | Revert Cloud Instance |
| Enterprise | T1537 | Transfer Data to Cloud Account |
| Enterprise | T1538 | Cloud Service Dashboard |
| Enterprise | T1539 | Steal Web Session Cookie |
| Mobile | T1540 | Code Injection |
| Mobile | T1541 | Foreground Persistence |
| Enterprise | T1542 | Pre-OS Boot |
| Enterprise | T1542.001 | System Firmware |
| Enterprise | T1542.002 | Component Firmware |
| Enterprise | T1542.003 | Bootkit |
| Enterprise | T1542.004 | ROMMONkit |
| Enterprise | T1542.005 | TFTP Boot |
| Enterprise | T1543 | Create or Modify System Process |
| Enterprise | T1543.001 | Launch Agent |
| Enterprise | T1543.002 | Systemd Service |
| Enterprise | T1543.003 | Windows Service |
| Enterprise | T1543.004 | Launch Daemon |
| Enterprise | T1543.005 | Container Service |
| Mobile | T1544 | Ingress Tool Transfer |
| Enterprise | T1546 | Event Triggered Execution |
| Enterprise | T1546.001 | Change Default File Association |
| Enterprise | T1546.002 | Screensaver |
| Enterprise | T1546.003 | Windows Management Instrumentation Event Subscription |
| Enterprise | T1546.004 | Unix Shell Configuration Modification |
| Enterprise | T1546.005 | Trap |
| Enterprise | T1546.006 | LC_LOAD_DYLIB Addition |
| Enterprise | T1546.007 | Netsh Helper DLL |
| Enterprise | T1546.008 | Accessibility Features |
| Enterprise | T1546.009 | AppCert DLLs |
| Enterprise | T1546.010 | AppInit DLLs |
| Enterprise | T1546.011 | Application Shimming |
| Enterprise | T1546.012 | Image File Execution Options Injection |
| Enterprise | T1546.013 | PowerShell Profile |
| Enterprise | T1546.014 | Emond |
| Enterprise | T1546.015 | Component Object Model Hijacking |
| Enterprise | T1546.016 | Installer Packages |
| Enterprise | T1546.017 | Udev Rules |
| Enterprise | T1546.018 | Python Startup Hooks |
| Enterprise | T1547 | Boot or Logon Autostart Execution |
| Enterprise | T1547.001 | Registry Run Keys / Startup Folder |
| Enterprise | T1547.002 | Authentication Package |
| Enterprise | T1547.003 | Time Providers |
| Enterprise | T1547.004 | Winlogon Helper DLL |
| Enterprise | T1547.005 | Security Support Provider |
| Enterprise | T1547.006 | Kernel Modules and Extensions |
| Enterprise | T1547.007 | Re-opened Applications |
| Enterprise | T1547.008 | LSASS Driver |
| Enterprise | T1547.009 | Shortcut Modification |
| Enterprise | T1547.010 | Port Monitors |
| Enterprise | T1547.011 | Plist Modification |
| Enterprise | T1547.012 | Print Processors |
| Enterprise | T1547.013 | XDG Autostart Entries |
| Enterprise | T1547.014 | Active Setup |
| Enterprise | T1547.015 | Login Items |
| Enterprise | T1548 | Abuse Elevation Control Mechanism |
| Enterprise | T1548.001 | Setuid and Setgid |
| Enterprise | T1548.002 | Bypass User Account Control |
| Enterprise | T1548.003 | Sudo and Sudo Caching |
| Enterprise | T1548.004 | Elevated Execution with Prompt |
| Enterprise | T1548.005 | Temporary Elevated Cloud Access |
| Enterprise | T1548.006 | TCC Manipulation |
| Enterprise | T1550 | Use Alternate Authentication Material |
| Enterprise | T1550.001 | Application Access Token |
| Enterprise | T1550.002 | Pass the Hash |
| Enterprise | T1550.003 | Pass the Ticket |
| Enterprise | T1550.004 | Web Session Cookie |
| Enterprise | T1552 | Unsecured Credentials |
| Enterprise | T1552.001 | Credentials In Files |
| Enterprise | T1552.002 | Credentials in Registry |
| Enterprise | T1552.003 | Shell History |
| Enterprise | T1552.004 | Private Keys |
| Enterprise | T1552.005 | Cloud Instance Metadata API |
| Enterprise | T1552.006 | Group Policy Preferences |
| Enterprise | T1552.007 | Container API |
| Enterprise | T1552.008 | Chat Messages |
| Enterprise | T1553 | Subvert Trust Controls |
| Enterprise | T1553.001 | Gatekeeper Bypass |
| Enterprise | T1553.002 | Code Signing |
| Enterprise | T1553.003 | SIP and Trust Provider Hijacking |
| Enterprise | T1553.004 | Install Root Certificate |
| Enterprise | T1553.005 | Mark-of-the-Web Bypass |
| Enterprise | T1553.006 | Code Signing Policy Modification |
| Enterprise | T1554 | Compromise Host Software Binary |
| Enterprise | T1555 | Credentials from Password Stores |
| Enterprise | T1555.001 | Keychain |
| Enterprise | T1555.002 | Securityd Memory |
| Enterprise | T1555.003 | Credentials from Web Browsers |
| Enterprise | T1555.004 | Windows Credential Manager |
| Enterprise | T1555.005 | Password Managers |
| Enterprise | T1555.006 | Cloud Secrets Management Stores |
| Enterprise | T1556 | Modify Authentication Process |
| Enterprise | T1556.001 | Domain Controller Authentication |
| Enterprise | T1556.002 | Password Filter DLL |
| Enterprise | T1556.003 | Pluggable Authentication Modules |
| Enterprise | T1556.004 | Network Device Authentication |
| Enterprise | T1556.005 | Reversible Encryption |
| Enterprise | T1556.006 | Multi-Factor Authentication |
| Enterprise | T1556.007 | Hybrid Identity |
| Enterprise | T1556.008 | Network Provider DLL |
| Enterprise | T1556.009 | Conditional Access Policies |
| Enterprise | T1557 | Adversary-in-the-Middle |
| Enterprise | T1557.001 | Name Resolution Poisoning and SMB Relay |
| Enterprise | T1557.002 | ARP Cache Poisoning |
| Enterprise | T1557.003 | DHCP Spoofing |
| Enterprise | T1557.004 | Evil Twin |
| Enterprise | T1558 | Steal or Forge Kerberos Tickets |
| Enterprise | T1558.001 | Golden Ticket |
| Enterprise | T1558.002 | Silver Ticket |
| Enterprise | T1558.003 | Kerberoasting |
| Enterprise | T1558.004 | AS-REP Roasting |
| Enterprise | T1558.005 | Ccache Files |
| Enterprise | T1559 | Inter-Process Communication |
| Enterprise | T1559.001 | Component Object Model |
| Enterprise | T1559.002 | Dynamic Data Exchange |
| Enterprise | T1559.003 | XPC Services |
| Enterprise | T1560 | Archive Collected Data |
| Enterprise | T1560.001 | Archive via Utility |
| Enterprise | T1560.002 | Archive via Library |
| Enterprise | T1560.003 | Archive via Custom Method |
| Enterprise | T1561 | Disk Wipe |
| Enterprise | T1561.001 | Disk Content Wipe |
| Enterprise | T1561.002 | Disk Structure Wipe |
| Enterprise | T1562 | Impair Defenses |
| Enterprise | T1562.001 | Disable or Modify Tools |
| Enterprise | T1562.002 | Disable Windows Event Logging |
| Enterprise | T1562.003 | Impair Command History Logging |
| Enterprise | T1562.004 | Disable or Modify System Firewall |
| Enterprise | T1562.006 | Indicator Blocking |
| Enterprise | T1562.007 | Disable or Modify Cloud Firewall |
| Enterprise | T1562.008 | Disable or Modify Cloud Logs |
| Enterprise | T1562.009 | Safe Mode Boot |
| Enterprise | T1562.010 | Downgrade Attack |
| Enterprise | T1562.011 | Spoof Security Alerting |
| Enterprise | T1562.012 | Disable or Modify Linux Audit System |
| Enterprise | T1562.013 | Disable or Modify Network Device Firewall |
| Enterprise | T1563 | Remote Service Session Hijacking |
| Enterprise | T1563.001 | SSH Hijacking |
| Enterprise | T1563.002 | RDP Hijacking |
| Enterprise | T1564 | Hide Artifacts |
| Enterprise | T1564.001 | Hidden Files and Directories |
| Enterprise | T1564.002 | Hidden Users |
| Enterprise | T1564.003 | Hidden Window |
| Enterprise | T1564.004 | NTFS File Attributes |
| Enterprise | T1564.005 | Hidden File System |
| Enterprise | T1564.006 | Run Virtual Instance |
| Enterprise | T1564.007 | VBA Stomping |
| Enterprise | T1564.008 | Email Hiding Rules |
| Enterprise | T1564.009 | Resource Forking |
| Enterprise | T1564.010 | Process Argument Spoofing |
| Enterprise | T1564.011 | Ignore Process Interrupts |
| Enterprise | T1564.012 | File/Path Exclusions |
| Enterprise | T1564.013 | Bind Mounts |
| Enterprise | T1564.014 | Extended Attributes |
| Enterprise | T1565 | Data Manipulation |
| Enterprise | T1565.001 | Stored Data Manipulation |
| Enterprise | T1565.002 | Transmitted Data Manipulation |
| Enterprise | T1565.003 | Runtime Data Manipulation |
| Enterprise | T1566 | Phishing |
| Enterprise | T1566.001 | Spearphishing Attachment |
| Enterprise | T1566.002 | Spearphishing Link |
| Enterprise | T1566.003 | Spearphishing via Service |
| Enterprise | T1566.004 | Spearphishing Voice |
| Enterprise | T1567 | Exfiltration Over Web Service |
| Enterprise | T1567.001 | Exfiltration to Code Repository |
| Enterprise | T1567.002 | Exfiltration to Cloud Storage |
| Enterprise | T1567.003 | Exfiltration to Text Storage Sites |
| Enterprise | T1567.004 | Exfiltration Over Webhook |
| Enterprise | T1568 | Dynamic Resolution |
| Enterprise | T1568.001 | Fast Flux DNS |
| Enterprise | T1568.002 | Domain Generation Algorithms |
| Enterprise | T1568.003 | DNS Calculation |
| Enterprise | T1569 | System Services |
| Enterprise | T1569.001 | Launchctl |
| Enterprise | T1569.002 | Service Execution |
| Enterprise | T1569.003 | Systemctl |
| Enterprise | T1570 | Lateral Tool Transfer |
| Enterprise | T1571 | Non-Standard Port |
| Enterprise | T1572 | Protocol Tunneling |
| Enterprise | T1573 | Encrypted Channel |
| Enterprise | T1573.001 | Symmetric Cryptography |
| Enterprise | T1573.002 | Asymmetric Cryptography |
| Enterprise | T1574 | Hijack Execution Flow |
| Enterprise | T1574.001 | DLL |
| Enterprise | T1574.002 | DLL Side-Loading |
| Enterprise | T1574.004 | Dylib Hijacking |
| Enterprise | T1574.005 | Executable Installer File Permissions Weakness |
| Enterprise | T1574.006 | Dynamic Linker Hijacking |
| Enterprise | T1574.007 | Path Interception by PATH Environment Variable |
| Enterprise | T1574.008 | Path Interception by Search Order Hijacking |
| Enterprise | T1574.009 | Path Interception by Unquoted Path |
| Enterprise | T1574.010 | Services File Permissions Weakness |
| Enterprise | T1574.011 | Services Registry Permissions Weakness |
| Enterprise | T1574.012 | COR_PROFILER |
| Enterprise | T1574.013 | KernelCallbackTable |
| Enterprise | T1574.014 | AppDomainManager |
| Mobile | T1575 | Native API |
| Mobile | T1576 | Uninstall Malicious Application |
| Mobile | T1577 | Compromise Application Executable |
| Enterprise | T1578 | Modify Cloud Compute Infrastructure |
| Enterprise | T1578.001 | Create Snapshot |
| Enterprise | T1578.002 | Create Cloud Instance |
| Enterprise | T1578.003 | Delete Cloud Instance |
| Enterprise | T1578.004 | Revert Cloud Instance |
| Enterprise | T1578.005 | Modify Cloud Compute Configurations |
| Mobile | T1579 | Keychain |
| Enterprise | T1580 | Cloud Infrastructure Discovery |
| Mobile | T1581 | Geofencing |
| Mobile | T1582 | SMS Control |
| Enterprise | T1583 | Acquire Infrastructure |
| Enterprise | T1583.001 | Domains |
| Enterprise | T1583.002 | DNS Server |
| Enterprise | T1583.003 | Virtual Private Server |
| Enterprise | T1583.004 | Server |
| Enterprise | T1583.005 | Botnet |
| Enterprise | T1583.006 | Web Services |
| Enterprise | T1583.007 | Serverless |
| Enterprise | T1583.008 | Malvertising |
| Enterprise | T1584 | Compromise Infrastructure |
| Enterprise | T1584.001 | Domains |
| Enterprise | T1584.002 | DNS Server |
| Enterprise | T1584.003 | Virtual Private Server |
| Enterprise | T1584.004 | Server |
| Enterprise | T1584.005 | Botnet |
| Enterprise | T1584.006 | Web Services |
| Enterprise | T1584.007 | Serverless |
| Enterprise | T1584.008 | Network Devices |
| Enterprise | T1585 | Establish Accounts |
| Enterprise | T1585.001 | Social Media Accounts |
| Enterprise | T1585.002 | Email Accounts |
| Enterprise | T1585.003 | Cloud Accounts |
| Enterprise | T1586 | Compromise Accounts |
| Enterprise | T1586.001 | Social Media Accounts |
| Enterprise | T1586.002 | Email Accounts |
| Enterprise | T1586.003 | Cloud Accounts |
| Enterprise | T1587 | Develop Capabilities |
| Enterprise | T1587.001 | Malware |
| Enterprise | T1587.002 | Code Signing Certificates |
| Enterprise | T1587.003 | Digital Certificates |
| Enterprise | T1587.004 | Exploits |
| Enterprise | T1588 | Obtain Capabilities |
| Enterprise | T1588.001 | Malware |
| Enterprise | T1588.002 | Tool |
| Enterprise | T1588.003 | Code Signing Certificates |
| Enterprise | T1588.004 | Digital Certificates |
| Enterprise | T1588.005 | Exploits |
| Enterprise | T1588.006 | Vulnerabilities |
| Enterprise | T1588.007 | Artificial Intelligence |
| Enterprise | T1589 | Gather Victim Identity Information |
| Enterprise | T1589.001 | Credentials |
| Enterprise | T1589.002 | Email Addresses |
| Enterprise | T1589.003 | Employee Names |
| Enterprise | T1590 | Gather Victim Network Information |
| Enterprise | T1590.001 | Domain Properties |
| Enterprise | T1590.002 | DNS |
| Enterprise | T1590.003 | Network Trust Dependencies |
| Enterprise | T1590.004 | Network Topology |
| Enterprise | T1590.005 | IP Addresses |
| Enterprise | T1590.006 | Network Security Appliances |
| Enterprise | T1591 | Gather Victim Org Information |
| Enterprise | T1591.001 | Determine Physical Locations |
| Enterprise | T1591.002 | Business Relationships |
| Enterprise | T1591.003 | Identify Business Tempo |
| Enterprise | T1591.004 | Identify Roles |
| Enterprise | T1592 | Gather Victim Host Information |
| Enterprise | T1592.001 | Hardware |
| Enterprise | T1592.002 | Software |
| Enterprise | T1592.003 | Firmware |
| Enterprise | T1592.004 | Client Configurations |
| Enterprise | T1593 | Search Open Websites/Domains |
| Enterprise | T1593.001 | Social Media |
| Enterprise | T1593.002 | Search Engines |
| Enterprise | T1593.003 | Code Repositories |
| Enterprise | T1594 | Search Victim-Owned Websites |
| Enterprise | T1595 | Active Scanning |
| Enterprise | T1595.001 | Scanning IP Blocks |
| Enterprise | T1595.002 | Vulnerability Scanning |
| Enterprise | T1595.003 | Wordlist Scanning |
| Enterprise | T1596 | Search Open Technical Databases |
| Enterprise | T1596.001 | DNS/Passive DNS |
| Enterprise | T1596.002 | WHOIS |
| Enterprise | T1596.003 | Digital Certificates |
| Enterprise | T1596.004 | CDNs |
| Enterprise | T1596.005 | Scan Databases |
| Enterprise | T1597 | Search Closed Sources |
| Enterprise | T1597.001 | Threat Intel Vendors |
| Enterprise | T1597.002 | Purchase Technical Data |
| Enterprise | T1598 | Phishing for Information |
| Enterprise | T1598.001 | Spearphishing Service |
| Enterprise | T1598.002 | Spearphishing Attachment |
| Enterprise | T1598.003 | Spearphishing Link |
| Enterprise | T1598.004 | Spearphishing Voice |
| Enterprise | T1599 | Network Boundary Bridging |
| Enterprise | T1599.001 | Network Address Translation Traversal |
| Enterprise | T1600 | Weaken Encryption |
| Enterprise | T1600.001 | Reduce Key Space |
| Enterprise | T1600.002 | Disable Crypto Hardware |
| Enterprise | T1601 | Modify System Image |
| Enterprise | T1601.001 | Patch System Image |
| Enterprise | T1601.002 | Downgrade System Image |
| Enterprise | T1602 | Data from Configuration Repository |
| Enterprise | T1602.001 | SNMP (MIB Dump) |
| Enterprise | T1602.002 | Network Device Configuration Dump |
| Mobile | T1603 | Scheduled Task/Job |
| Mobile | T1604 | Proxy Through Victim |
| Mobile | T1605 | Command-Line Interface |
| Enterprise | T1606 | Forge Web Credentials |
| Enterprise | T1606.001 | Web Cookies |
| Enterprise | T1606.002 | SAML Tokens |
| Enterprise | T1608 | Stage Capabilities |
| Enterprise | T1608.001 | Upload Malware |
| Enterprise | T1608.002 | Upload Tool |
| Enterprise | T1608.003 | Install Digital Certificate |
| Enterprise | T1608.004 | Drive-by Target |
| Enterprise | T1608.005 | Link Target |
| Enterprise | T1608.006 | SEO Poisoning |
| Enterprise | T1609 | Container Administration Command |
| Enterprise | T1610 | Deploy Container |
| Enterprise | T1611 | Escape to Host |
| Enterprise | T1612 | Build Image on Host |
| Enterprise | T1613 | Container and Resource Discovery |
| Enterprise | T1614 | System Location Discovery |
| Enterprise | T1614.001 | System Language Discovery |
| Enterprise | T1615 | Group Policy Discovery |
| Mobile | T1616 | Call Control |
| Mobile | T1617 | Hooking |
| Mobile | T1618 | User Evasion |
| Enterprise | T1619 | Cloud Storage Object Discovery |
| Enterprise | T1620 | Reflective Code Loading |
| Enterprise | T1621 | Multi-Factor Authentication Request Generation |
| Enterprise | T1622 | Debugger Evasion |
| Mobile | T1623 | Command and Scripting Interpreter |
| Mobile | T1623.001 | Unix Shell |
| Mobile | T1624 | Event Triggered Execution |
| Mobile | T1624.001 | Broadcast Receivers |
| Mobile | T1625 | Hijack Execution Flow |
| Mobile | T1625.001 | System Runtime API Hijacking |
| Mobile | T1626 | Abuse Elevation Control Mechanism |
| Mobile | T1626.001 | Device Administrator Permissions |
| Mobile | T1627 | Execution Guardrails |
| Mobile | T1627.001 | Geofencing |
| Mobile | T1628 | Hide Artifacts |
| Mobile | T1628.001 | Suppress Application Icon |
| Mobile | T1628.002 | User Evasion |
| Mobile | T1628.003 | Conceal Multimedia Files |
| Mobile | T1629 | Impair Defenses |
| Mobile | T1629.001 | Prevent Application Removal |
| Mobile | T1629.002 | Device Lockout |
| Mobile | T1629.003 | Disable or Modify Tools |
| Mobile | T1630 | Indicator Removal on Host |
| Mobile | T1630.001 | Uninstall Malicious Application |
| Mobile | T1630.002 | File Deletion |
| Mobile | T1630.003 | Disguise Root/Jailbreak Indicators |
| Mobile | T1631 | Process Injection |
| Mobile | T1631.001 | Ptrace System Calls |
| Mobile | T1632 | Subvert Trust Controls |
| Mobile | T1632.001 | Code Signing Policy Modification |
| Mobile | T1633 | Virtualization/Sandbox Evasion |
| Mobile | T1633.001 | System Checks |
| Mobile | T1634 | Credentials from Password Store |
| Mobile | T1634.001 | Keychain |
| Mobile | T1635 | Steal Application Access Token |
| Mobile | T1635.001 | URI Hijacking |
| Mobile | T1636 | Protected User Data |
| Mobile | T1636.001 | Calendar Entries |
| Mobile | T1636.002 | Call Log |
| Mobile | T1636.003 | Contact List |
| Mobile | T1636.004 | SMS Messages |
| Mobile | T1636.005 | Accounts |
| Mobile | T1637 | Dynamic Resolution |
| Mobile | T1637.001 | Domain Generation Algorithms |
| Mobile | T1638 | Adversary-in-the-Middle |
| Mobile | T1639 | Exfiltration Over Alternative Protocol |
| Mobile | T1639.001 | Exfiltration Over Unencrypted Non-C2 Protocol |
| Mobile | T1640 | Account Access Removal |
| Mobile | T1641 | Data Manipulation |
| Mobile | T1641.001 | Transmitted Data Manipulation |
| Mobile | T1642 | Endpoint Denial of Service |
| Mobile | T1643 | Generate Traffic from Victim |
| Mobile | T1644 | Out of Band Data |
| Mobile | T1645 | Compromise Client Software Binary |
| Mobile | T1646 | Exfiltration Over C2 Channel |
| Enterprise | T1647 | Plist File Modification |
| Enterprise | T1648 | Serverless Execution |
| Enterprise | T1649 | Steal or Forge Authentication Certificates |
| Enterprise | T1650 | Acquire Access |
| Enterprise | T1651 | Cloud Administration Command |
| Enterprise | T1652 | Device Driver Discovery |
| Enterprise | T1653 | Power Settings |
| Enterprise | T1654 | Log Enumeration |
| Mobile | T1655 | Masquerading |
| Mobile | T1655.001 | Match Legitimate Name or Location |
| Enterprise | T1656 | Impersonation |
| Enterprise | T1657 | Financial Theft |
| Mobile | T1658 | Exploitation for Client Execution |
| Enterprise | T1659 | Content Injection |
| Mobile | T1660 | Phishing |
| Mobile | T1661 | Application Versioning |
| Mobile | T1662 | Data Destruction |
| Mobile | T1663 | Remote Access Software |
| Mobile | T1664 | Exploitation for Initial Access |
| Enterprise | T1665 | Hide Infrastructure |
| Enterprise | T1666 | Modify Cloud Resource Hierarchy |
| Enterprise | T1667 | Email Bombing |
| Enterprise | T1668 | Exclusive Control |
| Enterprise | T1669 | Wi-Fi Networks |
| Mobile | T1670 | Virtualization Solution |
| Enterprise | T1671 | Cloud Application Integration |
| Enterprise | T1672 | Email Spoofing |
| Enterprise | T1673 | Virtual Machine Discovery |
| Enterprise | T1674 | Input Injection |
| Enterprise | T1675 | ESXi Administration Command |
| Mobile | T1676 | Linked Devices |
| Enterprise | T1677 | Poisoned Pipeline Execution |
| Enterprise | T1678 | Delay Execution |
| Enterprise | T1679 | Selective Exclusion |
| Enterprise | T1680 | Local Storage Discovery |
| Enterprise | T1681 | Search Threat Vendor Data |
| Enterprise | T1682 | Query Public AI Services |
| Enterprise | T1683 | Generate Content |
| Enterprise | T1683.001 | Written Content |
| Enterprise | T1683.002 | Audio-Visual Content |
| Enterprise | T1684 | Social Engineering |
| Enterprise | T1684.001 | Impersonation |
| Enterprise | T1684.002 | Email Spoofing |
| Enterprise | T1685 | Disable or Modify Tools |
| Enterprise | T1685.001 | Disable or Modify Windows Event Log |
| Enterprise | T1685.002 | Disable or Modify Cloud Log |
| Enterprise | T1685.003 | Modify or Spoof Tool UI |
| Enterprise | T1685.004 | Disable or Modify Linux Audit System Log |
| Enterprise | T1685.005 | Clear Windows Event Logs |
| Enterprise | T1685.006 | Clear Linux or Mac System Logs |
| Enterprise | T1686 | Disable or Modify System Firewall |
| Enterprise | T1686.001 | Cloud Firewall |
| Enterprise | T1686.002 | Network Device Firewall |
| Enterprise | T1686.003 | Windows Host Firewall |
| Enterprise | T1687 | Exploitation for Defense Impairment |
| Enterprise | T1688 | Safe Mode Boot |
| Enterprise | T1689 | Downgrade Attack |
| Enterprise | T1690 | Prevent Command History Logging |
| ICS | T1691 | Block Operational Technology Message |
| ICS | T1691.001 | Command Message |
| ICS | T1691.002 | Reporting Message |
| ICS | T1692 | Unauthorized Message |
| ICS | T1692.001 | Command Message |
| ICS | T1692.002 | Reporting Message |
| ICS | T1693 | Modify Firmware |
| ICS | T1693.001 | System Firmware |
| ICS | T1693.002 | Module Firmware |
| ICS | T1694 | Insecure Credentials |
| ICS | T1694.001 | Default Credentials |
| ICS | T1694.002 | Hardcoded Credentials |
| ICS | T1695 | Block Communications |
| ICS | T1695.001 | Serial COM |
| ICS | T1695.002 | Ethernet |
| ICS | T1695.003 | Wi-Fi |